Live data from Hacker News

Europe is scaling back GDPR and relaxing AI laws

theverge.com

661–670 of 1001 posts

Re: Europe is scaling back GDPR and relaxing AI laws

#661

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

Yes, the solution is clearer rules. What drives compliance costs up is rarely the compliance itself, it's usually the uncertainty about your being in compliance or not. That's also true for tax laws, labor laws, environment laws, almost every safety code out there, building zoning...

I totally agree with this view!

I understand why the rules are vague to an extent, simply because it is hard to impossible to cover every aspect of data collection.

But the GDPR is super vague on some very technical datapoints as well. Is an IP Address PII? Is there a difference between an IPv4 or an IPv6 address being PII? What constitutes as legitimate interest specifically? Can I use data for legitimate interests also for different first party purposes?

I‘ve spent more time than I care to admit navigating the compliance landscape of the GDPR and every time I consulted with compliance experts, I got different - partially conflicting - answers.

Re: Europe is scaling back GDPR and relaxing AI laws

#662
post #629

Earlier quoted context omitted.

The real issue with regulation isn’t the rules themselves; it’s who ends up writing them. And it’s almost always one of two groups: Politicians, who usually aren’t experts in the field. Industry leaders, who have every incentive to make the rules tougher for everyone.

Small company and business should be treated differently than big corp. And the fine and punishment should be adjusted accordingly.

While I generally agree, just differentiating the fines is not sufficient.

Small businesses in particular do not have staff or the capacity to to deal with a large amount of compliance overhead. The biggest help for small businesses (and large businesses alike) would probably be if the GDPR would be less vague on the rules surrounding typically collected data

Re: Europe is scaling back GDPR and relaxing AI laws

#663
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

I've stopped thinking of regulations as a single dial, where more regulations is bad or less regulations is bad. It entirely depends on what is being regulated and how. Some areas need more regulations, some areas need less. Some areas need altered regulation. Some areas have just the right regulations. Most regulations can be improved, some more than others.

Based take. It is rarely back and white when it comes to social-technical challenges like this.

Re: Europe is scaling back GDPR and relaxing AI laws

#664

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

I agree in theory but in practise, this just results in even more regulations. There are very few or no real world examples of stricter regulations being written in clearer terms. The reasons are numerous, but a big one is that people often have a financial incentive to circumvent these regulations. They attack the edge cases and the ambiguity between each word. If the regulations are not written sufficiently prescriptively, courts are swamped with cases and eventually a precedent is set which nullifies much or most of the intended purpose of the regulations. So regulators go to painstaking lengths to write clear and verbose regulations, but ensuring compliance with tens of thousands of pages of regulations are expensive, and this results in an economies of scale barrier for small businesses.

There are workarounds like exemptions for small businesses, but this creates all kinds of new issues like a regulatory ceiling, which results in enormous new costs on some arbitrary day for a business once it crosses some kind of user or revenue threshold. Ramp-ups are difficult or impossible to legislate in this context. Further, two or multi-tiered regulatory systems are highly inefficient and arguably unfair. They're very difficult for everyone to navigate. Generally speaking, from countless examples around the world, rules should apply to everyone.

Ultimately this means fewer regulations generally are good for startups - and larger businesses. But there are also social and consumer costs for this. There is no perfect balance to be found. Just competing ideological beliefs and positions.

Re: Europe is scaling back GDPR and relaxing AI laws

#665
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

The problems are in the details: why are news organizations exempt from this rule in Europe? You can’t read news websites unless you accept all cookies or pay to read.

Who decides these things? How is such a rule in favor of privacy? Why is my site where I regularly post news not eligible? Who decides which sites are eligible?

It’s these kind of moral double standards and cognitive dissonances that people have to endure. I wish it was black and white. But reality simply isn’t.

Re: Europe is scaling back GDPR and relaxing AI laws

#666

Earlier quoted context omitted.

That cookie banner needs to be standardized and offered by the browser. It should be like a certificate popup. Why is every website forced into doing a shoddy job ?

Aren’t tracking cookies mostly irrelevant nowadays, because every browser can be uniquely fingerprinted anyway?

Fingerprinting is actually covered by the regulations and needs to be "consented" to.

There are different regulations, but basically they are technology agnostic (a good thing). If you as a compnay want to use data that could theoretically be used as an identifyer for me, you need my consent. For any type of use. Except if it is absolutely necessary to provide the basic service. Or if we have a contractual relationship, but there are also protective rules in place to protect the customer.

Different regulations handle storing data (like cookies, but also local/session storage and similar things on the devices of your users. But those are separate from GDPR.

GDPR is - as said - only concerned with data that could be theoretically linked to me as an individual. Regardless what this data is. Could be an id in a cookie, could be a fingerprint, could be smoke signals. It could even be the combination of different data points, that taken together allow for an identification.

Theoretical example: Imagine I live in a village with 500 people. The company tracks the location and that I am male (so roughtly 50% of the population), that I am between 45 - 50 (say about 10% of the population), have multiple cats (say maybe only three people now in that village, use a Linux based machine - bingo: You found me. And now you have a set of data that falls under the GDPR. Welcome in having to ensure you only use this data in a way that I gave consent to.

See: The law doesn't even just look at marketing or tracking data. Or what happens in an app or a browser. It covers all data that is either pointing ti me as an "ID" - like a cookie ID, or at personal identifiable data - like bei combination in my example.

Re: Europe is scaling back GDPR and relaxing AI laws

#667
post #653

Earlier quoted context omitted.

Bad law enforced perfectly is also undesirable.

I'm not convinced. Perfect enforcement would be a great signal exposing bad law much more clearly, so it can be rewritten/scrapped.

Sure, but what about those who got hit by that bad law in the meantime?

Re: Europe is scaling back GDPR and relaxing AI laws

#668
post #412

Earlier quoted context omitted.

I disagree with this otherwise seemingly reasonable position. Draghi's latest report pointed out that overregulation is a major problem in the EU and costs EU companies the equivalent of a 50% tariff (if I remember correctly). Of course, Draghi's report has led to nothing more than a few headlines.

I’m not saying the following regarding Draghi’s report or particular regulation in mind: If an unethical business gets started due to underregulation and it generates revenue and contributes to GDP, is that a good thing?

That depends, are the people who are negatively impacted aware, and able to do anything about it?

There are some "mosquito" businesses that imho provide no net value and we'd be better off if they didn't exist (c.f. Bastiat's window breaker⁰). For example; payday loans, gadget insurance, MLMs, f2p games. The trouble is that there is an apparent need they're meeting, and nobody wants to "destroy jobs" or even worry too hard about exploiting the vulnerable.

Even if I were emperor and believed hese businesses were unjustifiably bad, I'd be worried about the authoritarian consequences of shutting down the less egregious ones. I'd also hope to have the humility to entertain the idea that I don't understand their full benefits.

In conclusion I think it's bad to have unethical businesses, and that even if they make the indicator go up, they are probably a net negative on the economy and society. However, I don't know what's to be done about it.

https://en.wikipedia.org/wiki/Parable_of_the_broken_window

Re: Europe is scaling back GDPR and relaxing AI laws

#669

Earlier quoted context omitted.

Most baffling thing is that sometimes you can't opt-out from "always active" stuff that still involve hundreds of "partners"; see: https://news.ycombinator.com/item?id=45844691

Users can opt-out by not using the service or buying an ad-free version if available. One would think that developers should not be forced to offer for free a version monetized with 60% less effective ads. And I understand currently this is indeed not the case for small developers, they can offer paid ad-free or free but with personalized ads. Large platforms apparently cannot.

If you want to do business in the EU, just follow the law.

You are not allowed to sell Heroin to anyone in Germany. I don't see you making the argument, that we should - in the same fashion as with digital spyware using companies - not target drug dealers. Becase hey, people can just decide to not buy drugs.

[Edit]: Typo

Re: Europe is scaling back GDPR and relaxing AI laws

#670
post #564
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

Are cookies really tracking you? 3rd party cookies don’t work in any browser. Ads are passing session data on the URLs instead. You can alow easily change some settings to stop persistent cookies. You can install privacy extensions like ghostery to block beacons. You can use features like ICloud private relay to prevent IP tracking. Solutions are all there and they aren’t because of any law.

There are a bunch of sites that stop working if you tweak privacy related settings. Twitter straight up tells you that if you experience problems, you should disable Firefox's tracking protection.
Post reply on HN